5. The Revenue You Don't Take
The forecast has a line in it for money you should not take.
Not fraud — nothing so crude. Legal money. Money your finance team has already modelled, your board has already seen, and your quarterly plan already depends on. The auto-renewal that fires at 3 a.m. on a card belonging to someone who forgot the trial existed. The overage charge that could have been prevented by a warning email you chose not to send, because the email costs nothing to send and roughly forty dollars a head to have sent. The twelve seats a customer stopped using in March and is still paying for in November. The cancellation flow that requires a phone call during business hours. The upsell that fires hardest at exactly the moment the customer is least able to evaluate it — the funeral home's casket display, the hospital discharge desk's payment plan, the travel insurance modal that appears after you have already entered your dying mother's address as the destination.
Every one of those is revenue. Every one is available. Most are lawful. All of them are, in the language of chapter two, a signal — just running in reverse. A company that will take money from a customer who did not intend to give it is telling you, at some expense to itself, exactly what it will do the next time your interest and its interest come apart. And the customer, who does not read your values page, reads that signal perfectly.
So here is the position this chapter argues, and it is less comfortable than the one you were expecting: most of your trust position is not made of things you did. It is made of money you declined to make. It is a negative — an absence — a P&L line that shows up nowhere except as a number that isn't there. Which means every deposit into the trust account has a name, an owner, and a defender in a room somewhere who has to explain why the number is lower than it could be. That person is the whole mechanism. Not your principles. That person.
The ceiling that nobody has to defend
Costco runs a rule that ought to be impossible: a hard ceiling on markup. Roughly fourteen percent on branded merchandise, around fifteen on its own Kirkland Signature line. Not a target, not a guideline — a ceiling. When the company's costs fall, the price on the shelf falls too, because the ceiling is expressed as a maximum over cost and there is nowhere for the surplus to go. Jim Sinegal, who ran the company for decades, told the story more than once about being pressed on why a product selling well at a good price shouldn't simply be priced higher, and the answer never varied: because the ceiling is the ceiling. The company also caps the number of items it stocks — a few thousand SKUs against a supermarket's tens of thousands — which is a second restraint most people never read as one. Fewer choices means every item has to earn its slot on price and quality rather than on slotting fees paid by a supplier.
Now notice what makes this work, because it is not virtue and it is not Sinegal.
The margin ceiling is survivable because the membership fee carries the profit. Costco's operating income depends heavily on membership renewals — the fees are close to pure margin, and the merchandise business runs thin by design to make the membership worth renewing. That is not a values statement. That is an architecture. The customer's interest and the company's interest have been deliberately soldered together at the level of the business model, so that the moment where they would ordinarily come apart — we could charge more for this and they'd still buy it — does not arrive as a temptation, because taking the extra margin degrades the only asset that actually pays.
This is the difference between restraint as a choice and restraint as a structure. In a company with restraint-as-choice, someone has to be brave every quarter. In Costco's case, no individual buyer has to be brave, because a buyer who wanted to breach the ceiling would have to go get an exception approved at the very top of the company, and the exception has been made famous internally as the thing that does not get approved. The bravery has been paid once, in the design, and then amortised across every pricing decision for forty years. Note the cost honestly: the model requires enormous volume, it forecloses whole categories of high-margin merchandise, and it is close to impossible to retrofit into a business whose profit already comes from the margin you would be capping. This is not a move you can copy on Friday. It is a demonstration of what the finished thing looks like.
The same company, both ways
Amazon will warn you that you already own the book. A small grey line appears under the buy button — you purchased this item on 14 March 2022 — and it costs Amazon the duplicate sale, at a scale where duplicate sales are not a rounding error. It is a genuine deposit. It is the kind of thing that shows up in customer anecdotes for a decade.
The same company built a cancellation flow for Prime that its own employees, in documents that later became public, referred to internally as "Iliad" — a name chosen for the length and difficulty of the journey. In September 2025, Amazon agreed to pay $2.5 billion to settle the FTC's case over enrolment and cancellation practices for Prime: a $1 billion civil penalty and $1.5 billion in refunds to consumers, without admitting wrongdoing. Whatever you believe about the merits, the number is the number, and it is roughly a thousand times what the duplicate-purchase warning has ever cost.
Hold both facts at once, because holding both is the point.
The reflex is to resolve the contradiction — to decide Amazon is really the warning or really the Iliad, to grade the company as trustworthy or not. Don't. The contradiction is not a contradiction; it is the ordinary condition of a large firm, and understanding why is the most useful thing in this chapter.
The duplicate-purchase warning lives in retail, in a team whose metric is long-run customer lifetime value and whose product leadership has spent twenty years arguing that trust is the reason people default to Amazon for a $9 purchase without comparison shopping. The cancellation flow lives in subscriptions, in a team whose metric is Prime net adds and retention, where every additional friction step measurably improves a number that somebody is graded on quarterly. Both teams are behaving rationally inside the incentive they were handed. Neither team is populated by better or worse people. There is no company making a moral choice here at all — there are two org units with different metrics, and the difference in their outputs is the difference in their metrics.
Which gives us the thing this chapter actually has to establish: restraint is not a moral property of firms. It cannot be, because the same firm exhibits it and its opposite at the same time, in the same year, under the same CEO, in the same product. Restraint is an artifact of who holds the authority to say no in a given decision, what that person is measured on, and whether the authority survives the next reorganisation. When the growth team gets the cancellation flow, cancellation gets harder. When the trust team gets it, cancellation gets easier. The values did not change. The org chart did.
Design the veto, not the values.
That is a harder instruction than it sounds, because a veto is an unpopular object. It is a person or a rule that can stop revenue, held by someone who does not carry the revenue number, and every reorganisation in the history of business has been an argument for consolidating decision rights under whoever owns the P&L. The veto is precisely the thing that reorganisation eats first. So it has to be built to be expensive to remove, which is chapter twelve's problem and I will not spend it here. What belongs here is the inventory: knowing which decisions need the veto in the first place.
Where the money comes from when the customer isn't looking
There is a small number of moments in any business where a customer is structurally unable to protect themselves, and revenue harvested from those moments is the highest-yield, lowest-trust money available. Every business has them. Most have never listed them. The list is short enough to write on one page, and writing it is a genuinely uncomfortable hour.
Renewal. The customer decided once, eleven months ago, and has not thought about you since. Anything you change between then and now — price, terms, plan structure — is a decision they are not present for. The question is not whether you are legally permitted to renew silently. It is whether the customer, shown the charge in advance, would have consented.
Cancellation. The customer has decided to leave and you control the exit. Every step you add converts some fraction of departures into another billing cycle. This is the single most reliable place in a subscription business to manufacture revenue and destroy trust simultaneously, and the exchange rate is terrible.
Bereavement. Someone has died and their accounts are still running. The industry that handles this worst is the one closest to it: funeral services, where the upsell arrives at the exact hour of maximum grief and minimum price sensitivity. But every subscription business has dead customers being billed, and almost none has a process for them that doesn't require the family to prove the death three times.
Medical and financial stress. Emergency-room billing, payday-adjacent credit, debt consolidation, hospital payment plans presented at discharge. The whole design of these products is that the buyer is in a state that impairs evaluation. If your product sells better to people under stress, that is a fact about your pricing and not about your product-market fit.
Forgotten subscriptions. The account with no login in fourteen months and a card on file. You know exactly who these people are; the data is trivially queryable. Every month you don't send the email is a month of revenue that arrived because someone forgot.
Dormant seats. The enterprise contract with 400 seats and 260 monthly actives. You have the telemetry. Your account manager has the telemetry. The renewal conversation is nine months away and the customer's champion has changed jobs twice.
Unwarned overage. Metered billing where the meter is visible to you in real time and to the customer at month end. The warning email is technically trivial and financially expensive, which is exactly the structure of a costly signal.
Now the practice that turns the inventory into a deposit: the proactive refund. The email that says you paid us $2,400 over the last eight months for a product you did not open once, so we have refunded it and paused your subscription. Nobody asked. Nobody complained. Nobody would ever have known.
What this buys is worth being precise about, because the case for it is not sentimental. First, it is a costly signal in the strict sense of chapter two — a company planning to harvest inattention could not afford to send it, so the signal is not imitable by your worst competitor. Second, it converts a customer who was going to churn angrily on discovery into one who churns gratefully, and the gratitude is durable in a way that a discount is not; departing customers talk more than staying ones. Third, it reaches the people who make purchase decisions elsewhere, because the person who forgot the subscription is frequently not the person who bought it. And fourth — the unglamorous one — it destroys the internal incentive to build a product that monetises non-use. A team that knows dormant revenue will be refunded stops optimising for dormancy. The refund is a governor on your own roadmap.
Price it honestly. If a meaningful share of your revenue comes from dormant accounts, refunding it is a revenue event with a real number, and it may be a number that changes your hiring plan. Say that out loud rather than discovering it in the board meeting. The move is defensible; pretending it's free is not.
Restraint in the funding model
Consumer Reports has been running the strongest version of this since 1936. It takes no advertising. It buys every product it tests at retail, anonymously, the way a customer would, rather than accepting review units from manufacturers. It does not permit its ratings to be used in advertising, and it has litigated to enforce that.
Look at what each rule does mechanically. No advertising removes the party whose money would create the conflict. Retail purchase removes the manufacturer's ability to send a hand-tuned unit — a form of corruption that requires no bribe and leaves no trace. The no-quoting-in-ads rule removes the incentive to give a good rating in order to be quoted. Three rules, each of which forecloses a specific and identifiable channel of influence, and none of which requires any individual tester to be incorruptible on any given Tuesday.
That is restraint built into the funding model rather than into the culture, and it is a materially different asset. Culture is a preference held by the people currently in the building. A funding model is a fact about where the money comes from, and it constrains people who have never heard the founding story. Consumer Reports has survived the collapse of nearly the entire independent-review business precisely because its constraint is financial rather than attitudinal — and it has paid for it continuously, in a subscriber-funded budget far smaller than an ad-funded one would have been, and in a permanent structural disadvantage against reviewers who take affiliate revenue on every click.
And restraint does not generalise
REI closes on Black Friday. It has done since 2015 — stores shut, staff paid, the day given over to a campaign telling people to go outside instead of shopping. The forgone revenue on the biggest retail day of the year is real and large, and the campaign has been enormously well received. It reads, correctly, as a company declining money.
REI has also spent recent years in a sustained labour conflict — union drives at multiple stores beginning in 2022, complaints filed with the National Labor Relations Board, and in 2024 a shareholder vote in which a majority of voting members declined to re-elect the board's nominated candidates, an unusual rebuke in a consumer cooperative. Whatever the merits of any particular dispute, the fact pattern matters for our purposes: a company famous for restraint toward customers found itself in open conflict with its own workers.
Customers do the arithmetic. Not because they are cynical, but because they are doing exactly what chapter one described — building a prediction about behaviour under pressure from whatever evidence is available. A closed store on Black Friday is evidence about the marketing budget. A contested union election is evidence about what happens when the cost of the promise lands on the operating line. Given both, a reasonable person weights the second more heavily, because it is the more expensive one. Restraint purchased in one dimension buys no immunity in another, and a highly visible restraint alongside a contested one reads worse than either alone — it invites the reading that the visible one was chosen because it was visible.
The operating lesson is not "don't close on Black Friday." It is that you cannot pick the dimension in which your restraint will be tested. Your customers, employees, suppliers, and regulators are all reading the same company, and they compare notes.
The failure mode: restraint as taste
Here is how this dies, and it dies this way almost every time.
The founder has a rule. Nobody wrote it down, because it was never a rule — it was a reflex. We don't charge for that. We don't dark-pattern the cancel button. If someone hasn't used it, we refund it. For six years the reflex holds, because the founder is in every pricing meeting and the company is small enough that the founder's face across a table is the enforcement mechanism.
Then the company hires a CFO, or takes on an investor, or the founder steps back into a chairman's role, or simply grows past the point where one person is in every meeting. And a competent person arrives with a spreadsheet — genuinely competent, acting in good faith, doing the job they were hired to do — and the spreadsheet identifies eleven million dollars of legally available revenue currently being declined for no documented reason. They ask, reasonably, what the reason is. And the answer that comes back is that's just not who we are, which is not an answer that survives contact with a spreadsheet, because it is not the same kind of object as a spreadsheet. It has no number on it. It cannot be defended in the terms the room is speaking.
So the restraint goes. Not in one decision — nobody would sign off on let's start exploiting our customers. It goes in eleven decisions over four quarters, each individually defensible, each with a named owner and a modelled uplift, and no single one of which anyone would call a betrayal. That is drift, and chapter seven is about it, but its origin is here: an undocumented restraint has no defender once the person whose taste it was leaves the room.
The counter-move is not to write down your values. Values documents are free to write, which by chapter two's logic means they are free to abandon, which means they signal nothing and defend nothing. The counter-move is to convert taste into three specific objects. A rule that fires by default, so that the extraction requires an action rather than the restraint requiring one — the dormant-account refund runs on a monthly cron and someone must intervene to stop it, rather than being a thing a good person remembers. A number that is forecast and reported, so the restraint appears in the plan as a line item with a name rather than as an absence that only shows up when someone goes looking for uplift. And an owner who does not carry the revenue target — because a veto held by the person whose bonus depends on overriding it is not a veto, it is a formality, and everyone in the room knows it.
Rule, number, owner. That is the whole apparatus. It is not more sophisticated than that, and companies that have it hold restraint through leadership changes that vaporise it everywhere else.
What to do this week
Go and pull the number.
Not a proxy for the number, not a directional read — the actual revenue recognised last month from customers who did not intend to pay you. Query it in four buckets, because the buckets have different owners and different fixes. Auto-renewals on accounts with no login in the preceding ninety days. Seats billed to enterprise contracts with no monthly activity. Overage charges on accounts that received no warning before the threshold was crossed. And cancellations that failed to complete — people who entered the flow and did not emerge, who are still being billed. Your data team can produce all four in an afternoon; the reason it has not been produced is not difficulty.
Then put the number in front of the person who owns it. Not in a strategy offsite, not in a values workshop, not in a deck about customer obsession. In a working meeting, with the person whose target that revenue counts against sitting in the room, because a restraint that has never been argued with a person who loses something by it has not actually been tested and you do not yet know whether you have one.
And then decide, in that meeting, what you refund. Not what you will stop doing next quarter — what money goes back, to whom, this month. Refunding is the only version of this decision that cannot be quietly reversed on the way out of the room. A policy change is a memo; a refund is a wire. It creates a fact in the ledger and a fact in a customer's inbox, and both of them are still there in a year when the person who authorised it has moved on.
Expect the meeting to be worse than you are imagining. The number is usually larger than the executives in the room believed, and the discovery is genuinely embarrassing — it means the company has been funding part of its growth from inattention and calling it retention. Sit in that rather than managing it. The discomfort is the information: it is the precise measure of the gap between what your company says it is and what your billing system does at 3 a.m. when nobody is watching. Your billing system is the honest one. It has been telling the truth about you to your customers this whole time.
And when the refund clears, write down the rule that would have prevented the charge, put a number on it in next year's plan, and hand it to someone who does not carry the quota. That is the deposit. It costs exactly what it costs, which is the reason it counts.
Brief 5.1 — The Extraction Map: Every Place Your Product Could Legally Take More Today
Somewhere in your product there is a switch that would add revenue this quarter and require no new engineering, no new legislation, and no new customer. A fee that could be charged for something currently free. A default that could be flipped. A renewal window that could shorten by eleven days. Somebody on your team already knows where it is, and has probably mentioned it once in a meeting where nobody wrote it down.
Build the list. One page: every place the product could legally take more money today, each line with the annual number attached and the reason it is declined.
The mechanism is that naming converts a diffuse temptation into a discrete, defended decision. Unmapped extraction gets taken one lever at a time, each move small enough to be defensible in isolation, and the aggregate never appears anywhere. This is precisely how the American banks arrived at reordering debit transactions from highest to lowest — a sequence of individually reasonable processing choices that, summed, maximised overdraft fees, and that cost several of them nine-figure settlements when the sum was finally displayed as a single object in a courtroom. The map does the displaying early, while it is still cheap. It also creates a record: once written, the organisation knows it declined, and a documented decline is the raw material of a policy. An undocumented one is a mood.
Two conditions. The number must be attached, because restraint without a magnitude cannot be defended against a forecast that has one. And the map must be owned by someone who does not carry a revenue target, or it will be read as an opportunity register — which is the failure mode.
That failure is worth stating plainly, because it is common and it is bad: the map becomes a roadmap. You hand a pressured finance function a tidy inventory of untaken money, and within two quarters three lines are gone. Guard against it structurally. The artifact lives with whoever holds the veto, each line carries its reason as prominently as its amount, and any line that moves from declined to taken requires the same signature as a pricing change.
Today: ask three people who would know — a support lead, a pricing analyst, your most senior engineer — the same question in writing. What could we charge for tomorrow that we don't? Ask separately. Collect the answers, don't discuss them yet. The overlap between three independent lists is where the real map starts.
Brief 5.2 — The Cancellation Test: Timing Your Own Churn Flow With a Stopwatch
You have never cancelled your own product. Somebody in the building has a live subscription — the growth team keeps one for testing — but no one has ever sat down, opened a stopwatch, and left.
Do that this week. Sign up as an ordinary customer through the ordinary funnel, then cancel, and record two numbers: seconds to subscribe, seconds to unsubscribe. Count screens, clicks, and required human contacts on each side. Report the ratio.
It works because a ratio is unarguable in a room where arguments are cheap. Forty seconds to join and eleven minutes plus a phone queue to leave is not an opinion about company values; it is a measurement, and it survives translation to a board, a journalist, and a regulator without alteration. That is the whole mechanism: asymmetry between entry and exit is the most legible available proxy for whether a company respects the word no, and unlike brand surveys it cannot be improved by talking. Notice also what the ratio measures upstream — a signup flow optimised to forty seconds represents real engineering investment, and the eleven minutes represents the absence of it. The gap is a budget allocation made visible.
Do not wait for the law to set the floor. The FTC's click-to-cancel provisions, finalised in 2024 to require cancellation as simple as enrolment, were vacated by the Eighth Circuit in 2025 on procedural grounds. California's automatic renewal statute still bites; the federal floor moved and then moved back. Which means the number is now yours to hold or not.
The failure mode is optimising the metric rather than the exit. A one-click cancel button that lands on a dead confirmation page, followed by nine days of win-back email, scores beautifully and insults the customer more efficiently than the phone queue did. The related trap is measuring only the web path when most of your actual churn is routed to a call centre precisely because the call centre saves more of it. Time the worst path, not the flagship one.
The condition for this to become an asset rather than a stunt: the ratio gets reported on the same cadence, by the same team, as activation. Once a year is theatre. Every month, next to signup conversion, is a control.
Today: cancel your own account. Write the two numbers in a message to your team with no commentary attached. The numbers will do it.
Brief 5.3 — Proactive Refunds: The Email That Costs Revenue and Buys a Decade
A customer signed a twelve-month contract in March and has logged in twice since May. Your systems know this with certainty; the usage table is right there next to the billing table. Renewal is in six weeks and it will process silently.
Build a rule that reaches out first. A scheduled query against usage, a threshold, a template, an automatic send: you've barely used this — here's a refund, or a smaller plan, or a pause. No approval queue, no discretion, no hero.
The mechanism is unusual and worth being precise about. Ordinary good service is ambiguous evidence, because a company that serves you well when you are watching may simply be competent at being watched. An unsolicited refund arrives at a moment when the customer had no expectation, no complaint filed, and no leverage whatsoever — which strips away every alternative explanation except that the firm actually decided against itself. That is what makes it disproportionately powerful relative to its cost: it is one of the few gestures that cannot be faked by a company that doesn't mean it, because the money is gone either way. Amazon has done a version of this for years, refunding video purchases customers never watched, and AWS's advisory tooling routinely tells customers to switch off resources they are paying for. Both cost real revenue. Both are cited by customers a decade later.
Two conditions. It must be automatic, because a manager doing it case by case is a person, not a policy, and people leave. And it must be real money — a credit that expires in ninety days is a retention offer wearing the costume of a refund, and customers read the difference instantly.
The failure mode is refunding your way out of a product problem. If low usage is chronic rather than idiosyncratic, the proactive refund becomes a subsidy that makes the underlying failure survivable, and it will delay the fix by exactly as long as it works. Watch the trend line, not the gesture: if the refunded cohort grows quarter over quarter, you have bought goodwill with money that should have gone to engineering.
The lesser trap: applying the rule only to small accounts, where it is affordable. That is a discount programme. The rule earns nothing until it fires on someone large.
Today: run one query — annual-plan accounts below ten percent utilisation at month nine — and total what they are paying you. That figure is the actual size of the decision you have been making by default.
Brief 5.4 — Writing a Markup Ceiling: Structural Restraint Inside Pricing Policy
Your pricing has no upper bound. It has a floor set by cost and a practical limit set by what customers tolerate, and every planning cycle someone competent is asked to find out whether the tolerance has moved. It usually has, slightly. This is how a fair price becomes an extractive one without anybody ever choosing extraction.
Write a numeric ceiling into pricing policy. A maximum gross margin — by line, by tier, by category — stated as a figure, approved by the board, and exceeded only by named exception.
Costco has run publicly on roughly this basis for decades: a cap reported for years at about fourteen percent on branded goods and fifteen percent on its own label, held even where demand would clearly carry more. The mechanism is not sentiment. A ceiling removes the annual question. Where price is bounded only by tolerance, it is renegotiated every cycle against a moving estimate of what the market bears, and the ratchet turns one way, because a price increase is always the cheapest revenue on the table — no product, no sales cycle, no new customer. A stated ceiling converts pricing from a recurring judgement into arithmetic, and arithmetic does not degrade when the judges change. That is the durability property you are buying: it survives the next VP of Pricing, who will not share the founder's instincts and should not have to.
For this to work the ceiling must sit below what you could charge. A cap set at the current maximum is a photograph, not a constraint. And it needs a slow, visible exceptions process rather than none, because an absolute rule with no valve gets quietly routed around the first time it genuinely bites.
The failure mode is capping the wrong number. Constrain product margin while the take migrates into fees, shipping, financing, currency spread, and ancillaries, and you have relocated the extraction while gaining the reputational credit for restraint. Airlines demonstrate this at scale. Cap total revenue per unit sold, inclusive of everything you collect, or the ceiling is decorative.
Today: pull twelve months of gross margin by SKU or plan tier and find the top decile. Ask what the ceiling would need to be to exclude it, what that would have cost, and whether the business would have survived the difference. If the answer is comfortably yes, you have found your number and confirmed you are already past it.
Brief 5.5 — Vulnerable Moment Inventory: Where Your Customer Cannot Properly Say No
Some fraction of your customers transact at a moment when refusal is not genuinely available to them. They are bereaved and arranging a funeral. They are three hours from having the heating cut off. They are in default and being called. They are inside a compulsion your product happens to serve. The techniques your growth team validated on browsing customers are being applied, unchanged, to these ones.
Inventory the moments. List every point of sale where the customer's capacity to decline is structurally compromised, and write a distinct rule for each.
Consent is the load-bearing member under the whole edifice of commerce, and the useful insight — the one the FCA built its 2021 vulnerability guidance around — is that it is a variable rather than a category. Vulnerability is situational and often temporary. It is not a type of person to be flagged in a CRM; it is a state that any customer can enter on any Tuesday and exit by Friday. Which means the correct unit of analysis is not the customer but the moment, and the operative question is not who is fragile but where in your journeys the ordinary machinery of persuasion stops being persuasion. Urgency framing on a browsing customer is marketing. The same banner on someone facing disconnection is coercion with better typography. The technique didn't change; the exit did.
Two conditions. Build the inventory from actual journeys — bereavement lines, collections queues, emergency callouts, the 2am chat channel — not from a workshop. And the resulting rule must be executable by a front-line person under pressure without looking anything up, which in practice means it has to be short: no upsell, no urgency language, no auto-renew enrolment on this path.
The failure mode is paternalism, and it is a real cost, not a hypothetical one. Decide a bereaved customer is too fragile to be sold to and you have denied an adult a thing they came to you for, on your assessment of their competence rather than theirs. Hold the line precisely: restrict the technique, never the access. They can buy anything. Nobody sells at them.
Today: pull last month's support transcripts and find five where the customer disclosed a crisis unprompted. Read what happened in the next four messages. That is your baseline, and it is more accurate than any policy document you currently hold.
Brief 5.6 — Who Holds the Veto? Naming the One Person Who Can Kill a Revenue Feature
There is a feature in your roadmap right now that is legal, tested, and worth real money, and that takes something from the customer they would not agree to if you asked them in a plain sentence. Several people are uneasy. None of them has the authority to stop it, and each is aware that objecting costs more than acquiescing.
Name one person with unilateral, unappealable authority to kill any shipped or planned revenue feature on customer-interest grounds. Put it in the org chart, in writing, with their actual name in the sentence.
Diffuse responsibility for restraint reliably produces none. Route the question to a committee and it approves, not through malice but through arithmetic: the cost of blocking is concentrated entirely on the blocker, while the benefit is spread thinly across a customer base that will never know the decision was made. Nobody in that structure is compensated for a bullet that didn't get fired. A named veto inverts the arithmetic. When killing bad revenue is your only job, your reputation attaches to what you let through, and the incentive gradient finally points the right way. This is the same structure as a captain's authority to refuse a departure, or a medical affairs sign-off in pharmaceuticals: one person, no appeal, career built on the record of refusals.
Three conditions, all of which the banks' second-line functions have failed at some point. Their compensation cannot touch revenue, or the veto has a price and the price will be found. The decision cannot be appealable to the CEO, or you have created an advisory role with an intimidating title. And they must be senior enough to survive exercising it — a veto that ends a career fires exactly once, and everyone watching learns the real rule.
The failure mode is dilution by volume. Give the veto fifty decisions a quarter and it will approve forty-nine, because sustained scrutiny is expensive and attention is finite. Restrict the scope hard: only features that change what the customer pays, what they are enrolled in, or what happens to their data. Everything else ships normally.
Today: write the sentence — [name] can kill any revenue feature, and no one can overturn it — and try each candidate in the blank. The name you cannot write without wincing tells you either who it should be or what your structure actually is. Both are useful findings.
Brief 5.7 — Dormant Accounts: The Quiet Line Item That Ends Careers
There is a cohort billing successfully every month who have not signed in for a year. In most subscription businesses it is a meaningful share of recurring revenue, and it carries the best unit economics in the entire book: no support tickets, no infrastructure load, no success manager, pure margin arriving on schedule.
Decide now, in writing, what happens at the dormancy threshold — notify, downgrade, or refund — and automate it before the next board meeting.
Dormant revenue is dangerous in a specific way that its size understates. It is simultaneously the highest-margin and the least-visible line you have, which means it grows without anyone ever deciding it should. Nobody proposed it. No meeting approved it. It simply accretes, quarter over quarter, until it is large enough that removing it requires courage rather than housekeeping — and by then the person who would need the courage has inherited the line rather than created it. That is the trap: the cost is deferred, lumpy, and arrives in a form that reads the accumulation backwards as intent. The regulator, the journalist, or the class action does not see a decision nobody made; it sees a decade of design. Careers end here, and they end not because the practice was illegal but because the pattern looked deliberate. Wells Fargo in 2016 is the genre in its clearest form: quiet account practices, a CEO out, compensation clawed back.
The law already agrees with the principle, incidentally. Escheatment statutes treat long-dormant balances as not really yours — the state takes custody on the owner's behalf. That is a settled legislative judgement that money nobody is using has a rightful holder who isn't you.
Set the threshold on a signal of actual use — sessions, not successful charges — and default the action toward the customer.
The failure mode is notification theatre: an email engineered to be ignored, sent to satisfy the policy rather than the person. It is testable, which is what makes it inexcusable. Check the open rate, then check what fraction of openers cancel. If almost nobody cancels after reading, the notice is not functioning as a notice and you already know it.
Today: count. Accounts billed in the last ninety days with zero sessions in three hundred and sixty-five. Multiply by ARPU. Then put that number in front of exactly one other person, which is the step that makes it real.
Brief 5.8 — Restraint With a Number: Reporting Declined Revenue to the Board as a Standing Line
Your board pack has bookings, pipeline, net revenue retention, and CAC payback. It has no line anywhere for the revenue you deliberately chose not to take. So every quarter, the extraction side of the ledger walks into the room carrying numbers and the restraint side walks in carrying an anecdote, and the outcome of that meeting was determined before it began.
Add a standing line: Declined Revenue, reported quarterly, with the three largest items named and the reason attached to each.
What gets reported is what gets defended. This is not a truism, it is a mechanism about advocacy under pressure — a quantity with an owner and a trend line has someone whose job is to explain its movement, and a quantity with neither has nobody. Making restraint a reported figure does three separate things. It converts an absence into an asset with a magnitude, which is the only form in which it can be weighed against a forecast. It creates a ratchet running the correct direction, because a line that appeared last quarter and vanished this quarter is a question somebody has to answer out loud. And the act of estimating forces the work — someone must actually model the foregone revenue, which means the restraint gets confirmed as real rather than assumed.
Conditions: it must be standing rather than requested, estimated conservatively, and presented by whoever holds the veto rather than by finance — the estimator should not be someone whose year improves when the number is large.
Which is the failure mode. Left ungoverned, the line inflates: every idea nobody was ever going to pursue gets counted as principled restraint, and within a year it is a vanity metric that costs nothing to produce. The discipline is narrow. An item qualifies only if a named person proposed it, someone modelled it, and it was then killed. If it never reached a model, it is not declined revenue. It is a thought.
There is a second, subtler failure: a board that reads the line as an admission of weak execution. Pre-empt it in the framing the first time you present. This is the maintenance cost of the pricing power on the previous page — the reason renewals close without discounting is that these lines exist.
Today: reconstruct last quarter's. Three items, three numbers, three reasons. If that reconstruction proves difficult, the difficulty is itself the diagnosis, and it is the finding worth reporting.
Brief 5.9 — Dark Pattern Rewrite: Turning a Confirmshaming Modal Into a Plain Sentence
A customer clicks cancel and a modal appears. The stay button is large and coloured. The leave button is small grey text reading No thanks, I like wasting money or I don't want to save $40. Someone wrote that sentence, someone approved it, and the test showed it lifted retention by a few points, so it has been sitting there for two years insulting people at the rate of several hundred a week.
Replace it with one plain sentence and two buttons of equal visual weight. Ship it this week; it is an afternoon of work.
Confirmshaming — Harry Brignull's term, part of the deceptive-design taxonomy he assembled — works by making refusal socially costly at the instant of refusal. It does convert. The A/B test is not lying to you. What the test cannot see is the second effect, which is the expensive one: the customer has just been shown, in the company's own voice, that this company is willing to manipulate them when the stakes are forty dollars. From that single observation they infer something about type, and the inference generalises to every other claim you make — your security page, your refund promise, your data policy, your explanation the next time something goes wrong. The damage is disproportionate because the evidence was so cheap to produce. Cheap signals are informative in exactly one direction: they cannot prove trustworthiness, but they can prove its absence at very low cost, and customers are excellent at this arithmetic even when they cannot articulate it.
The condition is visual parity. An honest sentence sitting above a grey link and a glowing button is still the pattern; the layout is making the argument the copy stopped making.
The failure mode is rewriting the words and keeping the mechanics. Soften the language while preserving the pre-checked box, the buried cancel link, the countdown that resets on reload, the extra required screen — and you have made the manipulation harder to identify without making it smaller. That is a worse position than where you started, because it defeats the customer's ability to detect it, which was the one protection they had.
Today: screenshot every screen between the cancel button and a completed cancellation. Read each aloud to a colleague, in your own voice, as though you were saying it to them. The lines you cannot say without adjusting your tone are the ones to rewrite. Your tone knows before you do.
Brief 5.10 — The Bad Quarter Protocol: What Gets Reached For First, and How to Pre-Commit Against It
Eight weeks into a quarter that will miss, the available money is always the same shape and everyone in the room knows it. Raise prices on the accounts with the highest switching costs. Loosen a data rule that was conservative anyway. Pull forward renewals not yet due. Extend the minimum term on new contracts. None of it is illegal, all of it is fast, and each item will be presented as a one-time adjustment to a temporary situation.
Write the list now, in a good quarter. Name the specific levers you will not reach for, and attach a mechanism that makes reaching for them require an act visible outside the room.
This is a Ulysses contract, and its logic deserves stating precisely because it is often mistaken for a values exercise. The person deciding in the bad quarter is not you. They hold different information, operate under real fear, and face a time horizon compressed to about six weeks — and no amount of character you install today survives contact with that. You are not trying to make them virtuous. You are raising the transaction cost of a specific choice so that the fastest path stops being the extractive one. The instruments that do this are unglamorous: a named lever list, a mandatory disclosure to the board or to affected customers, a waiting period long enough to outlast the quarter, and a signature that attaches to a person. Wells Fargo is the counterexample that proves the shape — the cross-sell targets held straight through the downturn, no valve existed, and the pressure travelled all the way down to the branch.
The failure mode is writing a values statement instead of a lever list. We always put customers first costs nothing to break and clarifies nothing at the moment of decision. We will not raise prices mid-contract on accounts with switching costs above X without ninety days notice and a board resolution is a fence, because it names the act, the threshold, and the friction.
The second failure is never revisiting it. A protocol nobody reviews becomes either quietly ignored or a hostage in a genuine emergency. Schedule the review annually, always in a good quarter, never in a bad one.
Today: write down the three levers you would reach for first. You already know them — that is the uncomfortable part. Date the list, send it to one colleague, and you have version one.
Essay 5.1
The prompt — Restraint ceases to build trust the moment it shifts from serving a customer’s actual outcome to managing a customer’s perceived risk, because declining revenue based on a judgment about what the customer should want replaces a market transaction with a paternal hierarchy. The tension sits precisely at the boundary where a firm’s expertise overrides a client’s agency: on one side, the responsible withdrawal of a harmful or misaligned offering preserves long-term value and prevents exploitation; on the other, that same withdrawal becomes a paternalistic gatekeeping that assumes superior knowledge, strips the buyer of corrective capacity, and ultimately breeds resentment when the buyer’s context diverges from the firm’s model. Trust degrades here not because the money was left on the table, but because the decision was made about the customer rather than for them, converting a voluntary exchange into a managed dependency.
What a serious answer has to do — The essay must establish a clear mechanism for distinguishing protective withdrawal from paternalistic overreach, grounding the distinction in observable customer outcomes rather than executive intent. It has to show how paternalism calcifies when firms remove pricing signals that would otherwise force market correction, and it must argue past the cheap defense that expertise inherently justifies discretion. Evidence must demonstrate how customers respond when options are removed under the guise of quality, and the essay must concede that expertise-based restraint inevitably contains blind spots where customer context outpaces institutional knowledge.
Where to look — Examine cases where regulated or semi-regulated industries voluntarily restrict product tiers, such as pharmaceutical companies limiting off-label promotion or fintech firms rejecting high-risk lending despite available capital. Trace the historical evolution of advisory standards in wealth management, particularly the shift from suitability to fiduciary norms, and study how algorithmic routing decisions in travel booking platforms balance margin optimization with consumer friction. Look to organizational psychology for the mechanisms of perceived paternalism and to behavioral economics for how loss aversion distorts the valuation of withheld options.
The length — 2,500 words minimum.
Essay 5.2
The prompt — A public company leaves money on the table when it systematises restraint, and the board’s fiduciary duty to maximise shareholder returns collides directly with the long-horizon accounting of trust, which registers those declines as deferred rather than realised value. The conflict is structural: shareholders demand quarterly compounding and view unearned revenue as a dead weight, while the firm’s competitive position depends on cumulative deposits that only crystallise during stress events. Neither side is wrong in isolation, but the contradiction explodes when the market discounts future trust at a rate higher than the cost of capital, forcing management to justify present restraint against visible underperformance.
What a serious answer has to do — The essay must map the accounting mechanism that converts deferred trust into measurable equity protection, showing how restraint functions as a real option rather than a sunk cost. It has to present evidence of how markets price voluntary revenue sacrifice, particularly in industries where reputation compounds asymmetrically, and it must argue past the standard shareholder critique that capital allocation should always maximise immediate cash flows. The response must also concede that public markets inherently discount long-horizon assets, and it must show how firms structurally insulate restraint from quarterly pressure through governance, compensation, or capital structure.
Where to look — Study capital allocation frameworks in asset management and insurance where reputation risk directly impacts cost of capital, and trace how sovereign wealth funds price long-term stability against short-cycle market volatility. Examine the historical pricing of initial public offerings where founders retained voting control to protect long-horizon strategies, and review board governance codes that mandate explicit consideration of stakeholder trust as a risk mitigation instrument. Look to corporate finance literature on intangible asset valuation and to behavioural finance for how market participants discount future reputation dividends.
The length — 2,500 words minimum.
Essay 5.3
The prompt — Junk fees persist not because operators lack ethics but because they represent a stable equilibrium where no single carrier can unilaterally lower displayed prices without losing price-sensitive customers to competitors, and breaking that equilibrium requires coordinated visibility rather than moral appeals. The mechanism is simple: when base fares are artificially suppressed to capture attention, ancillary charges absorb the margin, and any firm that attempts transparent pricing immediately faces a short-term volume shock while competitors retain the psychological advantage of low headline numbers. Consumers rationally optimise for headline price, carriers rationally optimise for total revenue, and the market settles into a fee structure that extracts maximum willingness to pay while minimising price sensitivity.
What a serious answer has to do — The essay must establish the game-theoretic mechanism that sustains fee fragmentation, showing how information asymmetry and search costs lock operators into a suboptimal but stable equilibrium. It has to demonstrate what actual coordination failures look like in practice, using cases where price transparency reforms altered market shares, and it must argue past the obvious solution of regulatory mandates that simply shift fees into new categories. The response must also concede that consumer price sensitivity remains structurally high, and it must show how platform architecture, not policy, redistributes the visibility of costs to break the equilibrium without external coercion.
Where to look — Analyse pricing architectures in airline ticketing, hotel booking, and event ticketing, focusing on how dynamic pricing engines and third-party aggregators distribute ancillary revenue. Review historical pricing reforms in telecommunications and cable, where bundling and fee transparency shifted market competition, and examine platform economics literature on how search costs and comparison tools alter consumer behaviour. Look to behavioural operations management for how default options and fee salience drive purchasing decisions, and study historical case studies of markets that transitioned from opaque to transparent pricing through platform competition rather than regulation.
The length — 2,500 words minimum.
Essay 5.4
The prompt — A company practising conspicuous restraint in pricing while extracting hard margins through data, support friction, or contract lock-ins eventually pays the contradiction in its entire cost of capital, because customers and markets price the whole organisation by its weakest trust signal rather than its strongest. The mechanism operates through signal integration: consumers do not evaluate corporate actions in isolation but aggregate them into a single credibility heuristic, and when restraint in one domain conflicts with extraction in another, the conflict resolves by discounting the restraint as marketing and the extraction as the true business model. Trust is not a portfolio of independent assets; it is a unified signal that prices the firm’s overall willingness to bear cost, and any extracted friction eventually reprices the withheld revenue as strategic deception.
What a serious answer has to do — The essay must establish the mechanism of signal integration, showing how markets aggregate disparate corporate actions into a single credibility price rather than evaluating them separately. It has to present evidence of how firms with mixed trust strategies experience rising customer acquisition costs and lower valuation multiples, and it must argue past the claim that conscious segmentation allows companies to maintain different trust profiles across product lines. The response must also concede that signal integration fails when customer segments are structurally isolated, and it must show how platform ecosystems and data linking inevitably unify the signal, forcing the entire organisation to bear the price of its lowest-trust extraction.
Where to look — Examine case studies of technology and financial services firms that introduced generous consumer policies while maintaining high-margin enterprise or premium tiers, and trace how market pricing adjusted when information asymmetry collapsed. Study historical pricing shifts in pharmaceuticals, where patient assistance programs coexisted with high list prices, and observe how regulatory scrutiny and public sentiment restructured corporate valuation. Look to behavioural marketing literature on signal consistency, to corporate finance on how reputation risk compounds into cost of capital, and to platform economics on how data integration unifies customer perception across touchpoints.
The length — 2,500 words minimum.
Essay 5.5
The prompt — Subscription businesses that profit materially from inactive accounts face a structural contradiction: their margin depends on customer forgetting, yet trust requires active alignment between what the customer wants and what the firm delivers, and operating on that misalignment eventually converts restraint into extraction. The mechanism is time-based: as accounts accumulate and usage declines, the firm’s incentive to maintain service quality decouples from the customer’s incentive to retain access, and the subscription model rewards frictionless renewal over active value delivery. Trust cannot sustain a business that monetises inattention, because the financial structure forces the firm to optimise for retention metrics rather than engagement, and the eventual realisation is that the firm has chosen a different business model than the one it markets.
What a serious answer has to do — The essay must establish the temporal mechanism that decouples subscription margins from active service delivery, showing how inactive accounts become profit centres that reward friction over value. It has to demonstrate how firms manage the tension between retention metrics and genuine engagement, using cases where subscription models faced trust erosion, and it must argue past the standard defence that low-usage accounts are simply priced for their option value. The response must also concede that some subscription models succeed by aligning pricing with actual usage tiers, and it must show how firms that ignore this alignment inevitably reprice their entire value proposition when customers recognise the structural contradiction.
Where to look — Study subscription economics in software, media, and fitness industries, focusing on how pricing structures handle inactive or low-usage accounts. Review historical cases where subscription models faced regulatory or market correction, such as streaming platforms adjusting pricing tiers or software companies introducing usage-based billing, and examine churn dynamics in recurring revenue models. Look to behavioural economics on the endowment effect and loss aversion in subscription contexts, to corporate finance on recurring revenue valuation, and to product management literature on how usage-based pricing aligns customer and firm incentives.
The length — 2,500 words minimum.